Matteoiammarrone maintains a small portfolio of web-based applications and gallery software, including S-CMS and IAMMA Simple Gallery, with a vulnerability profile centered on input-handling and access-control weaknesses. The recurring exposures span SQL injection, cross-site scripting, path traversal, and improper authentication—all characteristic of web-application layer flaws—and live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Matteoiammarrone over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4771HIGH SQL injection vulnerability to viewforum.php in S-CMS 2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Mar 23, 2011 | 7.5 | 32 | NO | YES |
CVE-2009-0864HIGH S-Cms 1.1 Stable allows remote attackers to bypass authentication and obtain administrative access via an OK value for the login cookie. | Mar 10, 2009 | 7.5 | 29 | NO | YES |
CVE-2009-1502HIGH Directory traversal vulnerability in plugin.php in S-Cms 1.1 Stable and 1.5.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences | May 1, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-0863HIGH SQL injection vulnerability in admin/delete_page.php in S-Cms 1.1 Stable allows remote attackers to execute arbitrary SQL commands via the id parameter. | Mar 10, 2009 | 7.5 | 28 | NO | YES |
CVE-2010-4772MEDIUM Cross-site scripting (XSS) vulnerability in blocks/lang.php in S-CMS 2.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter to viewforum.php. | Mar 23, 2011 | 4.3 | 24 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Matteoiammarrone.
Media articles that mention a CVE ID that affects a product developed by Matteoiammarrone — matched by CVE ID, not by vendor name.